Persistent malware can interfere with scans while Windows is running. Microsoft Defender Offline restarts into the Windows Recovery Environment, scans before the normal desktop loads and then starts Windows again. The screen changing or a restart finishing is not proof that a threat was removed. This guide treats the scan as one step in a response: preserve evidence, run the official option, read the result and decide what to do if symptoms continue.
Before you start
Save work and back up essential files without copying suspicious executables. Keep the BitLocker recovery key available and connect a laptop to power. Update Windows Security definitions while online if possible. If you suspect account theft, use a different trusted device to change critical passwords and revoke sessions; a scan on the affected PC cannot secure remote accounts.Do it step by step
- Open Windows Security > Virus & threat protection > Scan options and choose Microsoft Defender Antivirus (offline scan). Confirm the PC will restart.
- Allow the recovery environment scan to finish. Do not force power off because the display appears quiet for a while; note any error or recovery prompt.
- After Windows starts, open Windows Security > Protection history and read the latest action. Record the threat name, path, action and time if a detection exists.
- Run a normal updated scan and inspect startup apps, browser extensions and scheduled tasks only if symptoms suggest persistence. Do not delete random system files from a search result.
- If malware was found, isolate sensitive accounts and assess whether personal data was exposed. Restore affected documents from a known-good backup after the system is clean.
- If no threat appears but symptoms remain, gather logs, compare other user profiles and consider a supported repair or clean installation after backing up data.